Skip to content
pcreative Commerce

Your team: who gets into the panel

Each account has a role that the backend enforces on every request, and a status: a suspended account cannot sign in.

Panel → Account → Team. Everyone with an account to the panel, and the button to add more.

Each account has a role that the backend enforces on every request, and a status: a suspended account cannot sign in.

Adding someone

Add user, then fill in Full name, Email, Password and Role, and Create user.

  • The account works straight away, with that email and that password. There is no invitation: no email is sent. Passing the password on is up to you, and they can change it later with I forgot it on the sign-in page.
  • The password needs at least 10 characters, and the most common ones are refused.
  • If the email already has an account, it is refused.

What each role can do

RoleReadChange
Administratoreverythingeverything
Managereverything except the admin-only areascatalogue (products, variants, categories, stock, scanner), orders, returns, invoices, customers, reviews, abandoned carts, wishlists, balance, points, codes, newsletter, support, pages, blog, uploads and the marketplace
Usereverything except the admin-only areasorders, returns, order invoices, stock, scanner, support and reviews
Guesteverything except the admin-only areasnothing

Admin-only areas, for reading too: the team, payment settings and gateways, payouts to authors, extensions, migrations from another store, AI settings, erasing a customer's support data and the MCP entry point. Store configuration (taxes, shipping, regions, languages, legal texts, store settings, themes) can be read by everyone and changed only by an Administrator. So can installing or activating a theme and the panel's own settings.

Anything else answers 403 with "Your role on the team doesn't allow this". The check lives in the backend (apps/backend/src/propio/roles.ts), so it holds whatever calls the API.

A role change applies on the next request: there is no need to sign in again. The first account, created at installation, has no role stored and counts as Administrator; so does an account created with the rescue tool.

Suspending an account

Suspend account in the row's menu (or Status → Inactive in Edit user) closes all that person's sessions and stops them signing in; the password is still right, but the answer is "This account is suspended". Reactivate gives the access back. Pending does not block anything.

The store is never left without an administrator: you cannot suspend, demote or delete the last active Administrator, yourself included. Make someone else an administrator first.

Seller accounts

An account linked to a marketplace seller cannot manage the store: the backend refuses it every management request except its own ones, and it only works in the seller panel. Those accounts also appear in Team, because they are panel accounts too. How they are created is in Selling with others.

Editing and removing

View profile opens the person's page. Edit user changes the name, role, status, phone, location, department and bio.

On that page, Projects, Tasks done, Messages and Sign-in streak are fixed sample figures, not real data about the person. Export CSV in the list does nothing yet.

There is no button to delete an account. The backend can, through the management API:

DELETE /gestion/usuarios/<id>

It closes all their open sessions at that moment. It refuses to delete your own account, and to delete the last active Administrator.

If you are locked out

From the server, in apps/backend:

npm run rescate                            # who has access
npm run rescate -- alta you@example.com    # creates an account, shows its password once
npm run rescate -- clave you@example.com   # sets a new password, shows it once, reactivates it if suspended
npm run rescate -- admin you@example.com   # makes it an Administrator and reactivates it
npm run rescate -- cerrar you@example.com  # closes all their sessions

The list shows each account's role and whether it is suspended. admin is the way back in if the last administrator lost the role: from the server console the last-administrator rule does not apply. To shut someone out, suspend the account from the panel.

See also